summaryrefslogtreecommitdiff
path: root/src/server
diff options
context:
space:
mode:
authorMeiMei <30769358+mei23@users.noreply.github.com>2019-06-14 12:14:23 +0900
committersyuilo <Syuilotan@yahoo.co.jp>2019-06-14 12:14:23 +0900
commit67dda01fcb1fb3476eae9560d5c0404dc48c41f0 (patch)
treef77fa1caa000bad78d3aa837977950fcfee3e038 /src/server
parentサムネイル生成でエラーになってもファイルのアップロ... (diff)
downloadsharkey-67dda01fcb1fb3476eae9560d5c0404dc48c41f0.tar.gz
sharkey-67dda01fcb1fb3476eae9560d5c0404dc48c41f0.tar.bz2
sharkey-67dda01fcb1fb3476eae9560d5c0404dc48c41f0.zip
image以外はproxyしないように (#5051)
Diffstat (limited to 'src/server')
-rw-r--r--src/server/proxy/proxy-media.ts2
1 files changed, 2 insertions, 0 deletions
diff --git a/src/server/proxy/proxy-media.ts b/src/server/proxy/proxy-media.ts
index e16665f6cd..4535a0fb5d 100644
--- a/src/server/proxy/proxy-media.ts
+++ b/src/server/proxy/proxy-media.ts
@@ -17,6 +17,8 @@ export async function proxyMedia(ctx: Koa.BaseContext) {
const [type, ext] = await detectMine(path);
+ if (!type.startsWith('image/')) throw 403;
+
let image: IImage;
if ('static' in ctx.query && ['image/png', 'image/gif'].includes(type)) {